diff --git a/docs/faces.md b/docs/faces.md index 5ed7e7f..8069c9d 100644 --- a/docs/faces.md +++ b/docs/faces.md @@ -772,7 +772,18 @@ Steps 1–5 are the spike. Steps 6–8 are the build, and they are only justifie - **6 — done for storage.** Catalog schema v8 — `people`, `faces`, `face_person`, `face_person_rejected`, `face_calibration` — with the identity operations FR-CULL-10 requires. The `DetectFaces` job kind and the debounced clustering pass are not wired yet. -- **7, 8 — not started.** The People/Identity screen, and the route-C first-run flow. +- **7 — done.** The Identity screen: a third top-level mode beside library and develop, reached from + the library header. People rail, face grid with per-face confirm/reject, rename in place, confirm + all, split off a multi-selection, regroup, and the NFR-SEC-5 delete-everything control. +- **8 — not started.** The route-C first-run flow: no model fetch, no checksum pin, no licence + notice. The screen says "No face model installed" and stops, which is honest but is not the + feature. + +The screen taught the design one thing worth recording. **Splitting has to reject before it +confirms.** Moving faces to a new person is not enough on its own: the next clustering pass sees a +face that still looks like the person it left, suggests it back, and the user's correction becomes an +argument they keep having. §9's cannot-link constraint handles co-occurrence; this is the same idea +applied to a judgement the user made by hand. Two things the build changed in this document's own design: